A single, standardised file that tells anyone who finds a vulnerability in your systems exactly how to tell you — instead of guessing, or giving up.
security.txt is a short, plain-text file, defined by an official internet standard (RFC 9116), published at a fixed, predictable location — /.well-known/security.txt — on a domain. It lists a contact for security issues, and optionally an expiry date, a link to a disclosure policy, and other structured fields, in a format any automated tool or human researcher can read without needing to hunt for a "Contact Us" form first.
Contact: mailto:security@example.com Expires: 2027-09-12T00:00:00Z Canonical: https://example.com/.well-known/security.txt Preferred-Languages: en
Security researchers — and increasingly, automated scanners like the one on this page — find issues on websites all the time. Without a clear, published way to report one, a researcher who finds a real problem on your site faces a bad set of options: spend time hunting for a contact that might not exist, give up and say nothing, or post the finding publicly to get attention, which is the worst outcome for everyone. A security.txt file removes the guesswork and makes "tell us privately, here's exactly how" the obvious, easy path.
The scan looks for the file at its standard location, and falls back to the older, now-deprecated /security.txt path if the canonical one isn't there. If found, it checks that a contact field is actually present (a file with no way to reach anyone isn't much use), and that an Expires field exists and hasn't passed — the standard requires an expiry specifically so a stale, forgotten file with an outdated contact doesn't sit there indefinitely giving researchers a dead end.
Unlike most findings, this one comes with a shortcut: CBWatch can generate a valid, correctly-formatted security.txt file for your domain directly from the dashboard — enter the contact address you want to use, and it produces the file ready to upload to /.well-known/security.txt. There's no reason this particular gap should take longer than a couple of minutes to close.
This is one of the lowest-effort, lowest-risk items a scan can flag — it costs nothing, requires no code changes, and directly reduces the odds that a real vulnerability someone finds on your site ends up handled badly simply because they had no idea who to tell.
Want to know where your own domain stands? CBWatch checks this — and eight other categories — in about ten seconds, free, no signup.
Run a free scan →Want CBWatch to catch this automatically going forward? See what monitoring includes →